## 🦠 Malware Analysis & CTI [← Back to Index](../README.md) ### Malware Analysis Platforms Use these platforms to analyze suspicious files, URLs, or scripts, and identify malicious behavior, network activity, and indicators. - [VirusTotal](https://www.virustotal.com/) — Multi-engine malware scanner with IOC and sandbox integrations - [Hybrid Analysis](https://www.hybrid-analysis.com/) — Dynamic malware analysis platform showing behavior and network calls - [ANY.RUN](https://any.run/) — Interactive sandbox for live malware execution and observation - [Cuckoo Sandbox](https://cuckoosandbox.org/) — Open-source automated malware analysis system - [Intezer Analyze](https://analyze.intezer.com/) — Code-reuse and malware lineage analysis - [Joe Sandbox](https://www.joesecurity.org/) — Advanced commercial sandbox environment - [MalwareBazaar](https://bazaar.abuse.ch/) — Repository of malware samples and hashes ### Malware Analysis Tools Toolkits and utilities for static and dynamic analysis of binaries, scripts, and executables. - [Remnux](https://remnux.org/) — Linux distribution for reverse engineering and malware analysis - [YARA](https://virustotal.github.io/yara/) — Pattern-matching engine for malware detection and classification - [PEStudio](https://www.winitor.com/) — Windows executable analyzer for metadata and indicators - [Capa](https://github.com/mandiant/capa) — Detects capabilities and functionality in executable files - [Die (Detect It Easy)](https://github.com/horsicq/DIE-engine) — PE analysis tool for structure, entropy, and packers ### Reverse Engineering & Disassembly Tools for deep binary inspection, debugging, and reverse engineering of malware samples. - [Ghidra](https://ghidra-sre.org/) — Open-source reverse engineering suite developed by the NSA - [IDA Free](https://hex-rays.com/ida-free/) — Disassembler and debugger with visual graph analysis - [Binary Ninja](https://binary.ninja/) — Modern and scriptable reverse engineering platform - [x64dbg](https://x64dbg.com/) — Open-source Windows debugger for malware analysis ### Network & Behavior Analysis Monitor process activity, file system changes, and network communications of suspicious samples. - [Wireshark](https://www.wireshark.org/) — Network packet capture and protocol analyzer - [Procmon](https://learn.microsoft.com/en-us/sysinternals/downloads/procmon) — Real-time monitoring of file, registry, and process activity - [ApateDNS](https://www.fireeye.com/services/freeware/apatedns.html) — DNS redirection tool for malware network simulation - [FakeNet-NG](https://github.com/mandiant/flare-fakenet-ng) — Network emulation tool for capturing malware traffic ### Malware Feeds & Repositories Live sources of malware samples, indicators, and research materials. - [Malpedia](https://malpedia.caad.fkie.fraunhofer.de/) — Structured database of malware families and samples - [VX Underground](https://vx-underground.org/) — Archive of malware source code and research papers - [URLhaus](https://urlhaus.abuse.ch/) — Database of malicious URLs submitted by the community - [Feodo Tracker](https://feodotracker.abuse.ch/) — C2 tracking for banking trojans and botnets - [MalShare](https://malshare.com/) — Public malware repository with daily sample updates ### Threat Intelligence Platforms Platforms for collecting, structuring, and sharing threat intelligence data. - [MISP](https://www.misp-project.org/) — Open-source platform for sharing threat intelligence and IOCs - [OpenCTI](https://www.opencti.io/en/) — Knowledge graph for cyber threat intelligence management - [YETI](https://yeti-platform.github.io/) — Framework for storing and correlating threat data - [ThreatConnect](https://threatconnect.com/) — Commercial CTI platform with automation and analytics - [EclecticIQ Platform](https://www.eclecticiq.com/platform) — Enterprise-grade CTI management and analysis platform - [AboutIntel](https://www.aboutintel.com/) - Freemium TI and AS monitor to deliver relevant, actionable security insights. Without the noise. ### IOC Enrichment & Internet Scanners Tools for IOC enrichment, infrastructure mapping, and exposure analysis of malicious ecosystems. - [SilentPush](https://silentpush.com) - Track, monitor and counteract global threat activity. - [Validin](https://validin.com) - Explore and track threats across key attributes for public infrastructure tracking - [ThreatMiner](https://www.threatminer.org/) — Data mining for IOCs, malware, SSL, and related artifacts - [Abuse.ch](https://abuse.ch/) — Home to ThreatFox, Feodo Tracker, URLhaus, and SSLBL projects - [GreyNoise](https://www.greynoise.io/) — Contextual intelligence on internet-scanning IPs - [AlienVault OTX](https://otx.alienvault.com/) — Community threat intelligence sharing platform - [Maltiverse](https://maltiverse.com/) — IOC enrichment with threat classification and context - [Shodan](https://www.shodan.io/) — Internet-wide search engine for exposed systems - [Censys](https://censys.io/) — Search engine for internet infrastructure and certificates - [BinaryEdge](https://www.binaryedge.io/) — Real-time internet scanning and asset discovery for threat analysis - [CriminalIP](https://www.criminalip.io/) — Attack surface and exposure analysis platform - [FOFA](https://fofa.so/) — Cyber asset search engine widely used in China for exposure research - [Censys Workshop](https://workshop.censys.io/) — Research environment showcasing Censys experimental tools